Submitted:
22 June 2026
Posted:
22 June 2026
You are already at the latest version
Abstract
Keywords:
1. Introduction
Can we support efficient graph similarity matching over encrypted graph databases while allowing insertions, deletions, label updates, and periodic index re-randomization with forward and backward privacy?
- We formulate dynamic forward/backward-private PPGSQ. We extend the static graph similarity matching query model to support graph insertion, graph deletion, vertex/edge label update, and periodic re-randomization. We define the syntax, threat model, leakage functions, and privacy goals for dynamic encrypted graph similarity services.
- We design a dynamic branch-based encrypted index. DFB-PPGSQ constructs epoch-local feature tokens, per-record occurrence handles, encrypted branch-count vectors, update buffers, deletion tombstones, and a re-randomizable branch-tree index. The construction supports efficient filtering without forcing the cloud to traverse the whole database after each update.
- We integrate forward and backward privacy with graph filtering. Search tokens generated before an update cannot be used to identify future inserted or updated branch features. Future queries reveal only bounded information about deleted graphs. Periodic re-randomization further reduces long-term linkability of branch identifiers and tree nodes.
- We provide a reproducible prototype evaluation. We implement the protocol-relevant operations of DFB-PPGSQ in Python, including branch extraction, HMAC-based token generation, update buffering, tombstone filtering, epoch refresh, and generated dynamic sensor-topology workloads. The evaluation compares DFB-PPGSQ with static scan, static branch-tree, feature-only dynamic SSE, rebuild-after-update, and no-re-randomization baselines.
2. Related Work
2.1. Privacy-Preserving Graph Similarity Query
2.2. Dynamic Searchable Symmetric Encryption
2.3. Secure Graph Query Processing
2.4. Leakage Attacks and Motivation for Re-Randomization
| Scheme | Mechanism coverage | Residual risk | |||||
|---|---|---|---|---|---|---|---|
| Sim. | Dyn. | Label | Re-rand. | Fwd. | Bwd. | ||
| PGSim [3] | • | × | × | × | × | × | stable index leakage |
| PrigSim [4] | • | × | × | × | × | × | full-database traversal leakage |
| PPGSQ [5] | • | × | × | ∘ | × | × | static branch-token linkage |
| GraphShield [25] | × | • | ∘ | ∘ | • | ∘ | not designed for similarity filtering |
| Dynamic SSE index [17,21,22] | ∘ | • | ∘ | ∘ | • | ∘ | weak graph-structure pruning |
| DFB-PPGSQ | • | • | • | • | • | ∘ | same-epoch tombstone leakage |
3. Problem Formulation
3.1. System Model
Client.
Cloud.
- Insert: add a new graph G to the encrypted database;
- Delete: remove an existing graph from the active database;
- UpdateLabel: modify one or more vertex labels or edge labels in an active graph;
- Search: retrieve encrypted candidate graphs that satisfy the similarity threshold;
- ReRand: re-randomize feature tokens, occurrence handles, tree nodes, counters, and active-record handles at an epoch boundary.
3.2. Threat Model
3.3. Notation
3.4. Scheme Definition
.
.
.
.
.
.
.
3.5. Privacy Goals
Content privacy.
Query privacy.
Forward privacy.
Backward privacy.
Re-randomization privacy.
4. Preliminaries
4.1. Branch-Based Lower Bound of Edit Distance
4.2. Structured Encryption
4.3. Forward and Backward Privacy
4.4. Periodic Re-Randomization
5. The Proposed DFB-PPGSQ Scheme
5.1. Overview
- epoch-local feature tokens and per-record occurrence handles for compact active data in ;
- one-time update labels for recent insertions and label updates in ;
- epoch-specific deletion handles in ;
- re-randomization material for epoch migration.

5.2. Branch Extraction, Token Generation, and Setup
| Algorithm 1 Setup |
|
Input: master key K, initial graph database , vector length m, modulus p Output: encrypted database , branch-tree index , client state
|
5.3. Dynamic Branch-Tree Index
5.4. Forward-Private Insertion
5.5. Backward-Private Deletion
5.6. Label Update
| Algorithm 2 Dynamic Update |
|
Input: operation , epoch e, client state , outsourced state Output: updated outsourced state and client state
|
5.7. Query Processing
| Algorithm 3 Search |
|
Input: query graph Q, threshold , epoch e, state Output: encrypted candidate set
|
| Algorithm 4 Query in One Internal Node |
|
Input: query token and encrypted internal node Output: lower-bound score for node pruning
|
5.8. Periodic Re-Randomization
| Algorithm 5 Re-Randomization |
|
Input: epoch e, index , update buffer , tombstones , client state Output: refreshed index and cleared buffers
|
6. Security Analysis
6.1. Threat Model and Leakage Profile
6.2. Real-Ideal Security Definition
6.3. Token and Ciphertext Indistinguishability
6.4. Main Security Theorem
6.5. Forward Privacy
6.6. Backward Privacy
6.7. Query and Result Privacy
6.8. Re-Randomization Security
6.9. Comparison with Static PPGSQ-Style Indexing
7. Experimental Evaluation
7.1. Prototype Implementation and Workloads
| Component | Setting | Range / Value | Purpose |
|---|---|---|---|
| Graph database size | generated sensor-topology graphs | 250, 500, 1000, 2000, 4000 graphs | query scalability |
| Graph structure | connected sparse graph | 8–22 vertices; ring backbone plus random extra edges | sensor-network topology model |
| Stress profiles | mesh, industrial CPS, campus IoT | 1500–4000 graphs; mean 15–56 vertices | robustness to heterogeneous sensor networks |
| Dynamic operations | insert, delete, label update, epoch refresh | five random seeds: 1701–1705 | update and maintenance cost |
| Query threshold | graph edit-distance threshold proxy | pruning sensitivity | |
| Epoch length | refresh interval | 50, 100, 250, 500, 1000 updates | privacy-efficiency tradeoff |
7.2. Baselines
7.3. Metrics
7.4. Query Scalability
7.5. Dynamic Update Cost
7.6. Re-Randomization Tradeoff
7.7. Pruning Ability
7.8. Sensor-Network Stress Workloads
7.9. Leakage-Resilience
8. Conclusions
Supplementary Materials
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| DFB-PPGSQ | Dynamic Forward/Backward-Private Privacy-Preserving Graph Similarity Query |
| DSSE | Dynamic Searchable Symmetric Encryption |
| GED | Graph Edit Distance |
| HMAC | Hash-Based Message Authentication Code |
| IoT | Internet of Things |
| PPGSQ | Privacy-Preserving Graph Similarity Query |
| SSE | Searchable Symmetric Encryption |
References
- Li, S.; Song, H.; Iqbal, M. Privacy and Security for Resource-Constrained IoT Devices and Networks: Research Challenges and Opportunities. Sensors 2019, 19, 1935. [Google Scholar] [CrossRef] [PubMed]
- Wang, C.; Xing, S.; Gao, R.; Yan, L.; Xiong, N.; Wang, R. Disentangled Dynamic Deviation Transformer Networks for Multivariate Time Series Anomaly Detection. Sensors 2023, 23, 1104. [Google Scholar] [CrossRef] [PubMed]
- Zheng, Y.; Zhu, H.; Lu, R.; Guan, Y.; Zhang, S.; Wang, F.; Shao, J.; Li, H. PGSim: Efficient and Privacy-Preserving Graph Similarity Query Over Encrypted Data in Cloud. IEEE Trans. Inf. Forensics Secur. 2023, 18, 2030–2045. [Google Scholar] [CrossRef]
- Wang, S.; Zheng, Y.; Jia, X.; Huang, H.; Wang, C. PrigSim: Towards Privacy-Preserving Graph Similarity Search as a Cloud Service. IEEE Trans. Knowl. Data Eng. 2023, 35, 10478–10496. [Google Scholar] [CrossRef]
- Ge, X.; Yu, J.; Hao, R. Privacy-Preserving Graph Similarity Matching Query Over Encrypted Graph Database. IEEE Trans. Knowl. Data Eng. 2026, 38, 1932–1946. [Google Scholar] [CrossRef]
- Sanfeliu, A.; Fu, K.S. A Distance Measure Between Attributed Relational Graphs for Pattern Recognition. IEEE Trans. Syst. Man. Cybern. 1983, SMC-13, 353–362. [Google Scholar] [CrossRef]
- Gao, X.; Xiao, B.; Tao, D.; Li, X. A Survey of Graph Edit Distance. Pattern Anal. Appl. 2010, 13, 113–129. [Google Scholar] [CrossRef]
- Riesen, K.; Bunke, H. Approximate Graph Edit Distance Computation by Means of Bipartite Graph Matching. Image Vis. Comput. 2009, 27, 950–959. [Google Scholar] [CrossRef]
- Yan, X.; Yu, P.S.; Han, J. Graph Indexing: A Frequent Structure-Based Approach. In Proceedings of the Proceedings of the 2004 ACM SIGMOD International Conference on Management of Data, 2004; pp. 335–346. [Google Scholar] [CrossRef]
- Zheng, W.; Zou, L.; Lian, X.; Wang, D.; Zhao, D. Efficient Graph Similarity Search Over Large Graph Databases. IEEE Trans. Knowl. Data Eng. 2015, 27, 964–978. [Google Scholar] [CrossRef]
- Zhao, X.; Xiao, C.; Lin, X.; Wang, W. Efficient Graph Similarity Joins with Edit Distance Constraints. In Proceedings of the Proceedings of the 2012 IEEE 28th International Conference on Data Engineering, 2012; pp. 834–845. [Google Scholar] [CrossRef]
- Song, D.X.; Wagner, D.; Perrig, A. Practical Techniques for Searches on Encrypted Data. In Proceedings of the Proceedings of the 2000 IEEE Symposium on Security and Privacy, 2000; pp. 44–55. [Google Scholar] [CrossRef]
- Boneh, D.; Di Crescenzo, G.; Ostrovsky, R.; Persiano, G. Public Key Encryption with Keyword Search. In Proceedings of the Advances in Cryptology – EUROCRYPT 2004, 2004; pp. 506–522. [Google Scholar] [CrossRef]
- Chang, Y.C.; Mitzenmacher, M. Privacy Preserving Keyword Searches on Remote Encrypted Data. In Proceedings of the Applied Cryptography and Network Security, 2005; pp. 442–455. [Google Scholar] [CrossRef]
- Curtmola, R.; Garay, J.; Kamara, S.; Ostrovsky, R. Searchable Symmetric Encryption: Improved Definitions and Efficient Constructions. In Proceedings of the Proceedings of the 13th ACM Conference on Computer and Communications Security, 2006; pp. 79–88. [Google Scholar] [CrossRef]
- Cash, D.; Jarecki, S.; Jutla, C.; Krawczyk, H.; Rosu, M.C.; Steiner, M. Highly-Scalable Searchable Symmetric Encryption with Support for Boolean Queries. In Proceedings of the Advances in Cryptology – CRYPTO 2013, 2013; pp. 353–373. [Google Scholar] [CrossRef]
- Kamara, S.; Papamanthou, C.; Roeder, T. Dynamic Searchable Symmetric Encryption. In Proceedings of the Proceedings of the 2012 ACM Conference on Computer and Communications Security, 2012; pp. 965–976. [Google Scholar] [CrossRef]
- Kamara, S.; Papamanthou, C. Parallel and Dynamic Searchable Symmetric Encryption. In Proceedings of the Financial Cryptography and Data Security; 2013; pp. 258–274. [Google Scholar] [CrossRef]
- Cash, D.; Jaeger, J.; Jarecki, S.; Jutla, C.; Krawczyk, H.; Rosu, M.C.; Steiner, M. Dynamic Searchable Encryption in Very-Large Databases: Data Structures and Implementation. In Proceedings of the Proceedings of the 2014 Network and Distributed System Security Symposium, 2014. [Google Scholar] [CrossRef]
- Stefanov, E.; Papamanthou, C.; Shi, E. Practical Dynamic Searchable Encryption with Small Leakage. In Proceedings of the Proceedings of the 2014 Network and Distributed System Security Symposium, 2014. [Google Scholar] [CrossRef]
- Bost, R. Σoϕoς: Forward Secure Searchable Encryption. In Proceedings of the Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016; pp. 1143–1154. [Google Scholar] [CrossRef]
- Bost, R.; Minaud, B.; Ohrimenko, O. Forward and Backward Private Searchable Encryption from Constrained Cryptographic Primitives. In Proceedings of the Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017; pp. 1465–1482. [Google Scholar] [CrossRef]
- Cao, N.; Yang, Z.; Wang, C.; Ren, K.; Lou, W. Privacy-Preserving Query over Encrypted Graph-Structured Data in Cloud Computing. In Proceedings of the Proceedings of the 2011 IEEE 31st International Conference on Distributed Computing Systems, 2011; pp. 393–402. [Google Scholar] [CrossRef]
- Meng, X.; Kamara, S.; Nissim, K.; Kollios, G. GRECS: Graph Encryption for Approximate Shortest Distance Queries. In Proceedings of the Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015; pp. 504–517. [Google Scholar]
- Du, M.; Wu, S.; Wang, Q.; Chen, D.; Jiang, P.; Mohaisen, A. GraphShield: Dynamic Large Graphs for Secure Queries with Forward Privacy. IEEE Trans. Knowl. Data Eng. 2020, 1–1. [Google Scholar] [CrossRef]
- Falzon, F.; Ghosh, E.; Paterson, K.G.; Tamassia, R. PathGES: An Efficient and Secure Graph Encryption Scheme for Shortest Path Queries. In Proceedings of the Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security, 2024; pp. 4047–4061. [Google Scholar] [CrossRef]
- Yang, S. Privacy-Preserving Multi-User Graph Intersection Scheme for Wireless Communications in Cloud-Assisted Internet of Things. Sensors 2025, 25, 1892. [Google Scholar] [CrossRef] [PubMed]
- Cash, D.; Grubbs, P.; Perry, J.; Ristenpart, T. Leakage-Abuse Attacks against Searchable Encryption. In Proceedings of the Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015; pp. 668–679. [Google Scholar] [CrossRef]
- Naveed, M.; Kamara, S.; Wright, C.V. Inference Attacks on Property-Preserving Encrypted Databases. In Proceedings of the Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015; pp. 644–655. [Google Scholar] [CrossRef]
- Grubbs, P.; Lacharite, M.S.; Minaud, B.; Paterson, K.G. Learning to Reconstruct: Statistical Learning Theory and Encrypted Database Attacks. In Proceedings of the Proceedings of the 2019 IEEE Symposium on Security and Privacy, 2019; pp. 1067–1083. [Google Scholar] [CrossRef]
- Oya, S.; Kerschbaum, F. Hiding the Access Pattern is Not Enough: Exploiting Search Pattern Leakage in Searchable Encryption. In Proceedings of the Proceedings of the 30th USENIX Security Symposium, 2021; pp. 127–142. [Google Scholar]
- Lewi, K.; Wu, D.J. Order-Revealing Encryption. In Proceedings of the Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016; pp. 1167–1178. [Google Scholar] [CrossRef]
- Chase, M.; Kamara, S. Structured Encryption and Controlled Disclosure. In Proceedings of the Advances in Cryptology – ASIACRYPT 2010; 2010; pp. 577–594. [Google Scholar] [CrossRef]







| Symbol | Description |
|---|---|
| Security parameter | |
| Dynamic graph database at time t | |
| The i-th data graph | |
| Q | Query graph |
| Graph edit-distance threshold | |
| Branch multiset extracted from graph G | |
| b | A branch feature |
| e | Current epoch |
| Epoch key | |
| Epoch-local query-matchable feature token of branch b | |
| Per-record occurrence handle for the c-th occurrence of branch b in graph | |
| Encrypted branch-tree index in epoch e | |
| Encrypted update buffer in epoch e | |
| Deletion tombstone set in epoch e | |
| Branch-based lower bound of edit distance | |
| Dynamic operation type |
| Method | Mechanism profile | Purpose | ||
|---|---|---|---|---|
| Query | Update | Privacy | ||
| Static PPGSQ1-style | linear branch scan | rebuild only | content privacy | query-cost lower baseline |
| Static PPGSQ2-style | branch-tree pruning | rebuild only | content privacy | strongest static pruning baseline |
| Rebuild-after-update | branch-tree pruning | full rebuild | freshness | maintenance-cost upper baseline |
| DSSE-branch | feature-only lookup | dynamic update | forward privacy | cost of losing branch-tree pruning |
| No re-randomization | dynamic branch-tree | buffered update | partial privacy | value of epoch refresh |
| DFB-PPGSQ | dynamic branch-tree | buffer and compaction | forward/backward privacy | proposed construction |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).